不知道为什么,我的电脑总出现这个系列的病毒,每次关机之前总能扫描到30个,个个打不死的,很着急呀,现在人在国外,都没有人能帮忙的,希望大家能帮帮我.下面是我的日志.太长了,不好意思,我是菜鸟。。
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><; C:\WINDOWS\System32\ctfmon.exe> [Microsoft Corporation]
<Java Runtime Value><runjava.exe> []
<msnmsgr><; "C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [Microsoft Corporation]
<svc><C:\WINDOWS\svchost.exe> []
<Skype><"D:\DownLoads\Phone\Skype.exe" /nosplash /minimized> []
<MSNShell><D:\DownLoads\MSNShell\BIN\MSNShell.exe autorun> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
<Java Runtime Value><runjava.exe> []
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [Microsoft Corporation]
<PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [Microsoft Corporation]
<PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [Microsoft Corporation]
<Cmaudio><RunDll32 cmicnfg.cpl,CMICtrlWnd> []
<SoundMAXPnP><C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe> [Analog Devices, Inc.]
<SoundMAX><"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray> [Analog Devices, Inc.]
<ATIPTA><rem C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe> []
<SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe> [Synaptics, Inc.]
<SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> [Synaptics, Inc.]
<YDTMain.exe><rem C:\PROGRA~1\YDT\YDTMain.exe> []
<TkBellExe><"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot> [RealNetworks, Inc.]
<yassistse><"C:\PROGRA~1\Yahoo!\Assistant\yassistse.exe"> [Yahoo!]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> []
<spoolsv><C:\WINDOWS\System32\spoolsv\spoolsv.exe -printer> [广州傲讯信息科技有限公司]
<mscfs><RUNDLL32 C:\WINDOWS\System32\msibm\cfsys.dll,cfs> []
<kc32update><rundll32 C:\WINDOWS\System32\kc32update.dll,AppMain> []
<SurfAccuracy><C:\Program Files\SurfAccuracy\SAcc.exe> []
<ReJf5vH><C:\WINDOWS\rybyndev.exe> []
<BigDog303><C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)> []
<RavTask><"D:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<SVCHOST><C:\WINDOWS\System32\SVCH0ST.EXE> []
<17lelestart><C:\Program Files\VisionNet\17lele\system\play.exe 17LELEMIN> []
<RichMedia><C:\WINDOWS\System32\Rundll32.exe "C:\PROGRA~1\hbclient\HBHelper.dll",WaitWindows> [Shanghai Henbang Technology Co., Ltd]
<CnsMin><Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32> [北京三七二一科技有限公司]
<YLive.exe><C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe> [ ]
<system><C:\WINDOWS\System32\inetlnfo.exe> []
<helper.dll><C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
<DTService><rundll32.exe C:\DOCUME~1\vivi\LOCALS~1\Temp\XP158T~1.DLL,Load> []
<ip_sec><rundll32.exe C:\PROGRA~1\COMMON~1\system\msdc32.dll,_S1> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><EXPLORER.EXE> [Microsoft Corporation]
<Userinit><C:\WINDOWS\System32\Userinit.exe,> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><TopThemesLogonUI.exe> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
<{74F8B7BF-1576-4268-B90C-B77BDB6B783A}><C:\Program Files\Common Files\Microsoft Shared\MSINFO\MsInfo.rr> []
<{08315C1A-9BA9-4B7C-A432-26885F78DF28}><> []
<{5EED7056-B89D-4DE8-A060-D285EA746799}><C:\SPY_WOOOL\SPY_DLL.dll> []
<{7A238B14-A6F1-11E0-9A84-00C04FD8DBF8}><C:\WINDOWS\System32\RunCpl.DLL> []
<{99F1D023-7CEB-4586-80F7-BB1A98DB7602}><C:\Program Files\Internet Explorer\IEXPLORE.Sys> []
<{CF49F9F2-A8D3-464F-83EC-6AFC6573C267}><C:\WINDOWS\System32\inetinfo.dll> []
<{7A238B14-A6F1-11E0-9A84-00C04FD8DBD8}><C:\WINDOWS\System32\system.dll> []
<{D157330A-9EF3-49F8-9A67-4141AC41ADD4}><C:\WINDOWS\downlo~1\CnsHook.dll> [北京三七二一科技有限公司]
==================================
启动文件夹
[Microsoft Office]
<C:\Documents and Settings\All Users.WINDOWS\「开始」菜单\程序\启动\Microsoft Office.lnk><N>
==================================
服务
[ACU Configuration Service / ACS]
<C:\WINDOWS\System32\acs.exe><N/A>
[Ati HotKey Poller / Ati HotKey Poller]
<C:\WINDOWS\System32\Ati2evxx.exe><N/A>
[Cisco Systems, Inc. VPN Service / CVPND]
<D:\DownLoads\cvpnd.exe><Cisco Systems, Inc.>
[System Event Logger / DiRVIn]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[IBM PM Service / IBMPMSVC]
<C:\WINDOWS\System32\ibmpmsvc.exe><N/A>
[ClipManage / MouTALS]
<C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL,Export 1087><N/A>
[RegSrvc / RegSrvc]
<C:\WINDOWS\System32\RegSrvc.exe><Intel Corporation>
[Remote Lo / Remote Log]
<system32\ServeHost.exee><N/A>
[Rising Process Communication Center / RsCCenter]
<"D:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[RsRavMon Service / RsRavMon]
<"D:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Spectrum24 Event Monitor / S24EventMonitor]
<C:\WINDOWS\System32\S24EvMon.exe><Intel Corporation>
[SoundMAX Agent Service / SoundMAX Agent Service (default)]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[IBM KCU Service / TpKmpSVC]
<C:\WINDOWS\system32\TpKmpSVC.exe><N/A>
==================================
